Validated by a human, not flagged by a tool
A senior specialist reproduces every finding by hand, so what reaches your report is real, exploitable and worth fixing.
Your web application is where your customers, your revenue and your regulated data all meet, which is exactly why it is the first thing a serious attacker studies. We test it by hand: the authorisation logic, the multi-step business flows, the chained exploits a scanner will never reach. You get every finding proven with a working exploit, ranked by what it would actually cost you, and retested until it is closed.
How a web pentest worksProtected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
We’ll be in touch within one business day with next steps.
No se ha podido enviar. Inténtalo otra vez o escríbenos.















/api/orders/4813
Give a scanner your login page and it returns a missing security header. Give us the same login page and we return the order belonging to another one of your customers. That gap, between what a tool reports and what an attacker reaches, is why a manual pentest exists.
The flaws that cause real incidents rarely sit in a signature database. They live in your authorisation logic and your multi-step business flows. We reproduce each one, chain them where a chain exists, and hand your engineers the exact request, payload and fix path.
The trigger is a product launch, an audit clause, an enterprise customer’s security questionnaire, a board question, or an incident in your sector that made the risk suddenly concrete.
With ISO 27001, ENS, PCI DSS or SOC 2 on the line, the report has to survive scrutiny: traceable scope, methodology mapped to a recognised standard, signed retest and an execution certificate for the auditor folder.
When the ask is for assurance, you need an external, expert-led engagement and a deliverable that maps to business impact in language a non-technical stakeholder can read.
Every new surface ships with its own threat model. We test it before it is live, against the authorisation and tenancy logic a scanner cannot reason about, and retest after the fix so the release closes clean.
The question is not ‘do we have findings’ but ‘are there other paths’. We confirm the route that was used, or feared, is closed, and surface every adjacent vulnerability an attacker could pivot to.
We test the application the way the other side of the table would, so what you are taking on is evidence rather than an assurance, and the first serious finding does not arrive after the paperwork is signed.
Seven phases, the way we actually run them against a web application. The short version is below; your stack and its business context decide the path we take through it.
Most web pentests fail in one of four predictable ways. Here is how we close each gap.
A senior specialist reproduces every finding by hand, so what reaches your report is real, exploitable and worth fixing.
A medium-severity IDOR that exposes your customer table is a board problem, whatever CVSS says. We rank by what it costs you.
One document, no translation layer: a summary a CIO can take upward, and the request, payload and fix a developer can act on.
The retest is included, at no cost and with no time limit, tracked live in our platform, not buried in a PDF nobody reopens.
We at Etnia highly value our collaboration with Asperis Security.
Names, roles and companies on the record.
We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Tell us what you would like tested. An experienced consultant replies with a tailored scope, a fixed quote and a timeline.
A scanner matches your application against a database of known patterns and returns a list, most of it false positives, none of it interpreted. A pentest is a person reasoning about your specific application: reconnaissance, controlled exploitation, and the business-context judgement to know that a predictable order ID plus a missing authorisation check equals your entire customer table. The deliverable is a short list of findings that are genuinely exploitable in your environment, ranked by impact, each with a reproducible proof of concept. We use scanners to accelerate coverage during reconnaissance. We never ship you their output as the report.
Not without your explicit consent. Every engagement ships with documented Rules of Engagement: test windows, permitted intensity, forbidden actions and kill-switch contacts. In most cases we test a staging environment or a production mirror, and touch production only for read-only reconnaissance or explicitly authorised paths. Where exploitation in production is agreed, it runs under agreed rate limits with your team on standby, and we abort anything that risks availability.
Price follows scope, complexity and test type (black box, grey box or white box). We deliver a fixed-price proposal within 48 hours of the first call, with no hidden fees and no obligation to renew. A focused audit of a single application sits at the bottom of the range. Larger multi-tenant SaaS platforms or complex API estates scale from there. The retest is always included in the price.
Less than most teams expect. For a grey-box engagement, the usual choice, we ask for two test users per role, access to a staging environment or the production URL in scope, API documentation if you have it, and one technical contact for questions during the test. We bring the test data, tooling and reporting. A white-box engagement adds source-code access under NDA.
The specialist you meet on the first call. Our team holds OSCP, OSWE, OSEP, CRTO and CRTP credentials, most have worked inside enterprise security teams or research-led red teams, and we are NASA Bug Bounty verified contributors with published CVEs against widely deployed software. Your engagement is scoped, executed and retested by the same person throughout. That is who you speak to at every stage.
Annually as a compliance floor for ISO 27001, ENS, PCI DSS and SOC 2. In practice, cadence should follow how fast your application changes: teams shipping weekly benefit from continuous testing through the platform rather than a single yearly engagement. A fresh test is also warranted by any material change: a new authentication or SSO integration, a new B2B or admin portal, a first AI feature reaching production, or an incident in your sector.
We will review your attack surface, understand the business context around it, and define the right web pentest before the engagement begins.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Got it.
The web pentester who’d run your project will email you within one business day.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
Or email [email protected] directly.
OUR CLIENTS HAVE ALREADY DONE IT
We at Etnia highly value our collaboration with Asperis Security.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.
With Asperis you don’t hire a service. You hire a partner.
Pick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.